Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0252. PoCs published by ByALBAYX.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in eReservations via SQL injection using the credentials ' or '1 for both username and password fields.
Description
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in eReservations via SQL injection using the credentials ' or '1 for both username and password fields.